Improper Authentication in vCenter Server - CVE-2021-22012

 

Improper Authentication in vCenter Server - CVE-2021-22012

Published: September 21, 2021


Vulnerability identifier: #VU56801
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22012
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to missing authentication to the appliance management API. A remote non-authenticated attacker can with access to port 443/TCP can gain access to sensitive information on the system.


Affected software

vCenter Server
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
Dell EMC VxRail Appliance

How to mitigate CVE-2021-22012

Install updates from vendor's website.

vCenter Server - update to 6.5 U3q
EMC Integrated Data Protection Appliance - update to 2.7.0
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241

External References

Related Security Bulletins